Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Ubuntu 24.04: USN-7752-1 libyang2 Critical Denial Of Service CVE-2023-26916

ubuntu
Calendar Grey September 16, 2025
Dist Ubuntu Esm H88
Debian Security Advisory DSA-4849-1 tackles libyang1 issues with enhancements to mitigate potential system instability caused by specially constructed data entries.
libyang could be made to crash if it received specially crafted input.

Summary

libyang could be made to crash if it received specially crafted input.

Software Description:

- libyang2: parser toolkit for IETF YANG data modeling

Details:

It was discovered that libyang incorrectly handled certain memory

operations when parsing YANG strings. An attacker could possibly use this

issue to cause libyang to crash, resulting in a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  libyang2t64                     2.1.30-2.1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7752-1

CVE-2023-26916, CVE-2023-26917

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7752-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here